“Kimi” refers to the AI models; “Moonshot AI” is the company that developed them. The Kimi AI models are software (large language models) that generate responses to your prompts. Moonshot AI — formally Beijing Moonshot AI Technology Co., Ltd. — is based in Beijing, China.
Bells Up AI uses two U.S.-hosted inference routes for Kimi: Amazon Bedrock and Fireworks AI. The route that processes your request depends on the model you select. Moonshot AI itself never receives your prompts, documents, or the models’ responses.
Across both routes, your prompts and responses stay within U.S. infrastructure and are not disclosed to Moonshot AI. Neither provider trains on your content under the terms described below. Model output censorship concerns and regulatory uncertainty persist regardless of hosting.
| Question | Answer |
|---|---|
| Which inference route processes your request? | Amazon Bedrock: Kimi K2.5 and Kimi K2 Thinking, in a U.S. region. Fireworks AI: Kimi K3, through its U.S.-only endpoint. |
| Can Moonshot AI access your prompts or documents? | No — Moonshot AI never receives them |
| Can Moonshot AI train AI on your prompts or documents? | No — Moonshot AI has zero access |
| Can Moonshot AI employees or contractors review your data? | No — Moonshot AI has zero access |
| How long does Moonshot AI retain your data? | N/A — Moonshot AI never receives your data |
| How does each route retain inference content? | Amazon Bedrock: zero data retention by default. Fireworks AI: zero data retention for inference; prompt-cache data may remain in volatile memory for several minutes, but is not logged to persistent storage. |
| Does the infrastructure provider train AI on your data? | No — prohibited by contract for both |
| How do the routes handle safety and abuse? | Amazon Bedrock: automated classifiers may scan content; its zero operator access (ZOA) model prevents AWS operators from accessing inputs or outputs. Fireworks AI: its terms allow safety-screening tools. (Bedrock details; Fireworks details) |
| Can provider personnel review prompts or responses? | Amazon Bedrock: its ZOA model bars operator access; apparent CSAM may be reviewed for confirmation and reporting. Fireworks AI: its terms say it will not log content for human review, except as required by law or to provide the service or support. |
| Is this disclosure legal advice? | No. Bells Up AI does not provide legal advice. Attorneys should exercise independent professional judgment regarding model selection. |
Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Amazon Web Services and Fireworks AI — the platforms that run the models and where your prompts are processed — each hold SOC 2 and ISO 27001 certifications.
Bells Up AI gives customers access to a range of AI tools and the information needed to make informed professional decisions about their use. Model selection remains the attorney’s professional judgment call.
The model developer does not receive your data. Bells Up AI accesses the Kimi models through Amazon Bedrock (Kimi K2.5, Kimi K2 Thinking) and Fireworks AI (Kimi K3). Moonshot AI — the company that develops and trains the Kimi models — does not receive the prompts, documents, or responses you submit through Bells Up AI, does not store them, and cannot train on them. Processing stays within U.S. infrastructure. See Moonshot AI: The Model Developer and Fireworks AI: The Infrastructure Provider for Kimi K3 for the basis of each statement.
Model behavior is unaffected by hosting. Output censorship and bias arise from the trained model and are not changed by running Kimi on Moonshot AI’s servers, Amazon’s, or Fireworks AI’s. In December 2025, NIST’s Center for AI Standards and Innovation (CAISI) reported that Kimi K2 Thinking’s Chinese-language output was censored at a level comparable to the most-censored PRC models CAISI tested, while its English-language output was relatively uncensored. A separate academic benchmark found censorship of Taiwan-sovereignty framing in both languages. These findings are conditional and language-dependent, not a single fixed rate. Separately, the vendor SplxAI rated the raw Kimi K2 model poorly on its safety tests. That is a vendor finding, not a government or academic study. See What U.S.-Hosted Inference Does and Does Not Address for the full analysis.
Regulatory context. As of this review, Moonshot AI is not on the U.S. Commerce Department’s BIS Entity List and has not been designated by the Department of Defense under Section 1260H. Alibaba and Tencent, two of Moonshot AI’s largest investors, do appear on the Section 1260H list; Moonshot AI does not. Moonshot AI is the subject of an open federal inquiry. In July 2026, U.S. officials alleged that it used another developer’s model outputs and export-restricted computing hardware to build Kimi K3; the Bureau of Industry and Security opened an investigation, and the Treasury Secretary stated publicly on July 22, 2026 that sanctions and an Entity List designation were on the table. No charges, sanctions, or export-control penalties have been imposed as of this review, and independent analysts have questioned the timeline underlying the distillation allegation. This matter is unresolved and could change.
Texas added Moonshot AI to its state prohibited-technology list in January 2026. That restriction applies to state-government devices and networks, not private or commercial use. As of the Last Reviewed date, Bells Up AI has not identified a U.S. restriction on private or commercial use of Kimi. The proposed “No Adversarial AI Act” (H.R. 4142 / S. 2177) would apply to federal-agency procurement only; it remains in committee and has not been enacted. See Chinese-Origin Model Considerations for the full analysis.
Practice considerations. Kimi runs on U.S. infrastructure. Moonshot AI does not receive your prompts, documents, or responses, and the infrastructure providers do not train on them under the terms described below. Model output requires separate consideration. Verify Kimi responses on politically sensitive topics before relying on them for high-stakes client work. Moonshot AI does not appear on the BIS Entity List or the Section 1260H list, but the federal inquiry described above is open, and attorneys may wish to weigh both that inquiry and how the use of a Chinese-origin model could be perceived by clients, opposing counsel, or a court. Attorneys with government, defense, or export-control-adjacent clients should consider the inquiry’s possible outcomes, including the effect an adverse outcome could have on the continued availability of the Kimi models.
When you use the Kimi family of AI models through Bells Up AI, the following parties are involved in processing your request:
Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.
What Moonshot AI Does: Moonshot AI develops and trains the Kimi family of AI models. Moonshot AI provides the trained model weights for deployment on infrastructure it does not control. Kimi K3 is open-weight under the Kimi K3 License, and Kimi K2.5 and Kimi K2 Thinking are open-weight under their respective licenses — meaning the model weights are publicly available. Moonshot AI has no proprietary access channel to the copies of these models deployed on Amazon Bedrock or Fireworks AI.
“Open weights” means the trained model can be downloaded and run by anyone — including us, on infrastructure the developer cannot access. It does not mean the training data or methods are disclosed. How any modern AI model was trained, open-weight or proprietary, cannot be independently verified from the model itself. In practical terms, the open-weight structure is what makes it possible for Amazon and Fireworks AI to host Kimi on infrastructure that Moonshot AI itself cannot reach — it is the reason the isolation described below is available at all.
Moonshot AI cannot access your prompts, documents, or Kimi’s responses when you use Kimi through Bells Up AI. For Kimi K2.5 and Kimi K2 Thinking, hosted on Amazon Bedrock, this is a technical restriction: Moonshot AI has no access to the Amazon infrastructure where those models are deployed. For Kimi K3 on Fireworks AI, the basis is contractual and is described in Fireworks AI: The Infrastructure Provider for Kimi K3.
On Amazon Bedrock, Amazon does not provide Moonshot AI with access to your prompts, documents, or responses. In order to run AI models like the Kimi models you access through Bells Up AI, Amazon maintains “Model Deployment Accounts”, which model developers like Moonshot AI do not have access to:
“Model providers don’t have any access to those accounts. After delivery of a model from a model provider to [Amazon], Amazon Bedrock will perform a deep copy of a model provider’s inference and training software into those accounts for deployment. Because the model providers don’t have access to those accounts, they don’t have access to Amazon Bedrock logs or to customer prompts and completions.”
Amazon Bedrock prohibits both Amazon and third-party model providers from using your prompts, documents, or model responses for training:
Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are “stored and processed by AWS and are not shared with third-party model providers.”
Moonshot AI’s own Kimi services (kimi.com and platform.kimi.ai) operate under different terms. By default, those services train on your content (Moonshot AI’s terms describe this as helping to “optimize our models”); a training opt-out is available only through enterprise negotiation, not as a self-service setting; there is no fixed retention schedule; and data is stored on servers located in Singapore. Bells Up AI runs Kimi on Amazon Bedrock or Fireworks AI infrastructure, and Moonshot AI does not receive your data.
Moonshot AI is headquartered in Beijing, China. As a Chinese company, Moonshot AI is subject to Chinese national security and data laws. Attorneys should understand what these laws require, and why U.S.-hosted inference matters in this context.
National Intelligence Law (2017, amended 2018):
“All organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law.”
Data Security Law (2021): Classifies data and imposes handling requirements on Chinese companies. Compels data disclosure to authorities under national security provisions.
Personal Information Protection Law (PIPL, 2021): China’s data protection framework, with explicit carve-outs for national security and public interest that allow government access to personal data held by Chinese companies.
These laws allow Chinese authorities to compel Moonshot AI to disclose data. Moonshot AI does not possess your inference data — your prompts, documents, and Kimi’s responses never reach Moonshot AI’s systems. Chinese authorities cannot compel disclosure of data Moonshot AI does not have.
Moonshot AI’s own services and U.S.-hosted Kimi use different data flows:
| Concern | Direct Kimi API | Through Bells Up AI (U.S.-hosted) |
|---|---|---|
| Moonshot AI receives prompt data | Yes | No |
| Data stored outside the United States | Yes — Singapore | No — processed in the United States |
| Chinese gov’t can compel data disclosure | Yes, via Moonshot AI | No data for Moonshot AI to disclose |
| Data used for model training | Yes, by default (per Moonshot AI ToS) | No (prohibited by contract) |
This comparison addresses the Kimi models hosted on Amazon Bedrock (Kimi K2.5, Kimi K2 Thinking). Kimi K3 runs on Fireworks AI; see Fireworks AI: The Infrastructure Provider for Kimi K3 for Kimi K3.
U.S.-hosted inference prevents:
It does not address:
In July 2026, U.S. government officials publicly alleged that Moonshot AI used another AI developer’s model outputs (a technique known as distillation) and export-restricted computing hardware to develop Kimi K3. No charges, sanctions, or export-control penalties have been imposed as of this review, and independent analysts have questioned the timeline underlying the distillation claim. The allegations concern how the Kimi models were trained, not how your prompts and responses are handled when you use them; the data-handling protections described here are unaffected.
September 2026 federal advisory. On September 8, 2026, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation issued a joint cybersecurity advisory, AA26-251A, titled “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies.” The advisory names six China-based AI companies — DeepSeek, Moonshot AI, Alibaba, Z.AI, MiniMax, and StepFun — that it states extracted training data from U.S. frontier models. It states that Moonshot AI, since at least mid-2025, “extracted significant Claude Fable 5 data to train its Kimi-K3 model and GPT-4o data to train its Kimi-K2 model.” The advisory directs its recommendations to U.S. AI developers, on detecting and responding to distillation. It imposes no restriction, obligation, or requirement on companies or individuals that use these models. It concerns how these models were trained, not how your prompts and responses are handled when you use them; the data-handling protections described in this disclosure are unaffected.
Amazon provides two distinct services relevant to how your data is handled:
What Amazon Bedrock Does: Amazon Bedrock is the service that hosts and runs Kimi K2.5 and Kimi K2 Thinking. When you submit a prompt to one of these models, Bells Up AI sends it to Amazon Bedrock, which processes it through Kimi and returns the response.
The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service, not to Fireworks AI or the selected model. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are not sent to this service.
Amazon Bedrock’s Core Commitments:
No Storage of Your Prompts or Responses:
“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output. Also, Amazon Bedrock uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs.”
No Training on Your Data:
Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are “stored and processed by AWS and are not shared with third-party model providers.”
Data Stays in Region: Your data remains in the Amazon data center region where the request is processed. Bells Up AI processes Kimi K2.5 and Kimi K2 Thinking requests in the United States AWS region us-east-1 (Northern Virginia). This is a U.S. region; your requests are not routed outside the United States.
Amazon Bedrock runs automated content scanning on data processed through the service. If that scanning flags apparent child sexual abuse material, the AWS Service Terms provide:
“If we detect apparent child sexual abuse material (“CSAM”), you agree and instruct that we may: (a) review the flagged input or output to determine if it is CSAM, and (b) report the incident to the National Center for Missing and Exploited Children or other authority.”
The Service Terms also provide that, for certain models identified on Amazon’s Bedrock abuse-detection documentation, Amazon Bedrock stores inputs and outputs for up to 30 days to detect terms-of-service violations and may review them if a potential violation is detected. None of the models available through Bells Up AI are identified on that list as of this review.
Apart from these provisions, Amazon’s abuse-detection documentation describes the following data-security model:
“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output.”
What this means:
This automated scanning is narrower in scope than the abuse monitoring systems used by direct API providers like OpenAI or Google, which retain data for up to 30 or 55 days and may involve human review of flagged content. Amazon Bedrock’s abuse detection operates at the infrastructure level and does not involve the model provider (Moonshot AI).
While Moonshot AI never receives the content of your prompts or responses, Amazon may share non-content usage information with third-party model providers:
“We may share information, that does not include Your Content, about your use of a third-party model with the provider of that third-party model.”
This metadata may include identifiers such as Bells Up AI’s AWS Account ID, the AWS region, the model used, request counts, token usage, and timestamps. It contains no content from your prompts, documents, or responses.
What This Means: Separately from Amazon Bedrock, the Bells Up AI application itself runs on Amazon’s cloud infrastructure. This includes:
Can Amazon Access This Data?
Amazon operates the physical servers and storage infrastructure we use. Amazon’s access to data stored on its infrastructure is governed by contract and verified by independent audits, which test whether Amazon’s actual practices match its contractual commitments:
“AWS will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order).”
This prohibits Amazon from using your data to develop Amazon’s own AI or other products, or from providing your data to others for such purposes.
Amazon’s SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.
Technical Protections:
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all communications |
| Encryption at rest | AES-256 for all stored data |
| Server storage | Encrypted at the hardware level |
| Access controls | Credentials managed through Amazon’s identity system; no hardcoded passwords |
Bells Up AI’s use of Amazon services is governed by:
Under the Data Processing Addendum, Amazon acts as a “data processor” — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.
Amazon Bedrock and the underlying infrastructure maintain the following certifications:
Kimi K3 is not hosted on Amazon Bedrock. Bells Up AI runs Kimi K3 through Fireworks AI, an independent U.S. inference platform, on Fireworks’ U.S.-only endpoint. The other Kimi models described above (Kimi K2.5, Kimi K2 Thinking) run on Amazon Bedrock.
Fireworks’ binding Terms of Service commit to a zero-data-retention policy for inference:
“We have adopted a ‘Zero Data Retention’ policy, which means that we will not, unless otherwise required by Applicable Law (or to provide the Service or support to you): (i) log your Content for human review; or (ii) retain your Content, beyond the time it takes to generate Output and deliver that Output to you.”
Fireworks’ Data Processing Addendum states the same obligation in binding contract terms:
“Except as described below, Company shall not retain Customer’s prompt inputs or model outputs beyond the lifecycle of the applicable request.”
Fireworks’ zero-retention commitment applies to standard inference. Two Fireworks features handle data beyond the request itself. Its Response API retains data unless the caller sets the request to non-storing (“store=false”); Bells Up AI sends “store=false”. Prompt caching is enabled by default on all Fireworks models and cannot be turned off. Fireworks states that when caching is active, some prompt data and the associated key-value caches “can be stored in volatile memory for several minutes,” and that prompt and generation data “are not logged into any persistent storage.” Serverless deployments maintain a separate cache for each Fireworks account. Fireworks’ zero-retention policy carves out what is necessary to provide the service (Section 3.6), and its Data Processing Addendum identifies prompt caching as such a feature (Section 4.5), so Kimi K3 traffic runs under the zero-retention commitment as Fireworks defines it. Fireworks’ Terms of Service also reserve the right to use “safety screening tools on the Content as [Fireworks] deem[s] appropriate” (Section 3.6).
Fireworks’ Terms of Service provide that “We will not use your Content to train our own models or to improve the Service,” and its Data Processing Addendum separately prohibits “using Covered Data to train, fine-tune, or otherwise improve any shared or foundational model” (Section 4.3(f)) — language not limited to Fireworks’ own models.
Bells Up AI runs all Kimi K3 inference through Fireworks’ US-only Serverless endpoint, the Fireworks product that “serves inference exclusively from the US.” See US-only Serverless, Fireworks AI documentation.
Moonshot AI does not receive your prompts, documents, or Kimi K3’s responses, because Fireworks’ Data Processing Addendum restricts processing of your data to its authorized sub-processors, and Moonshot AI is not one (Section 6.2 and Schedule 4).
We encourage you to review the source documents:
| Document | What It Covers | Link |
|---|---|---|
| AWS Bedrock Third-Party Model Terms | General third-party model terms and conditions for Bedrock | View |
| Amazon Bedrock Data Protection | No-storage, no-training, no-access commitments (Kimi K2.5, Kimi K2 Thinking) | View |
| Amazon Web Services Service Terms | Bedrock-specific terms (Section 50.12), abuse detection, metadata sharing | View |
| Amazon Web Services Data Processing Addendum | Amazon’s role as processor, access limitations | View |
| Fireworks AI Terms of Service | Zero-data-retention policy (Section 3.6); no training on your content (Kimi K3) | View |
| Fireworks AI Data Processing Addendum | Retention limits (Section 4.5), prohibited uses (Section 4.3(f)), authorized sub-processors (Schedule 4) | View |
| Amazon Bedrock Security & Compliance | Certifications (SOC, ISO, HIPAA) | View |
| China’s National Intelligence Law (English translation) | Legal obligations on Chinese organizations | View |
| NCSC/DNI Bulletin on PRC Laws | US intelligence community analysis of Chinese data laws | View |
If you have questions about how your data is protected when using Kimi through Bells Up AI, contact us at info@bellsup.ai.
This disclosure covers Kimi models accessed through Amazon Bedrock and Fireworks AI. It does not cover Moonshot AI’s direct services. See each model family’s disclosure for information about other models available through Bells Up AI.
This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.
The regulatory and policy landscape for Chinese-origin AI models is evolving. Bells Up AI reviews this disclosure periodically, but attorneys should independently verify current regulatory requirements. The “Last Reviewed” date above reflects when this document was last updated.